Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-5822

Опубликовано: 27 июн. 2024
Источник: nvd
CVSS3: 7.3
CVSS3: 9.8
EPSS Низкий

Описание

A Server-Side Request Forgery (SSRF) vulnerability exists in the upload processing interface of gaizhenbiao/ChuanhuChatGPT versions <= ChuanhuChatGPT-20240410-git.zip. This vulnerability allows attackers to send crafted requests from the vulnerable server to internal or external resources, potentially bypassing security controls and accessing sensitive data.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:gaizhenbiao:chuanhuchatgpt:20240410:*:*:*:*:*:*:*

EPSS

Процентиль: 12%
0.0004
Низкий

7.3 High

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 7.3
github
больше 1 года назад

A Server-Side Request Forgery (SSRF) vulnerability exists in the upload processing interface of gaizhenbiao/ChuanhuChatGPT versions <= ChuanhuChatGPT-20240410-git.zip. This vulnerability allows attackers to send crafted requests from the vulnerable server to internal or external resources, potentially bypassing security controls and accessing sensitive data.

EPSS

Процентиль: 12%
0.0004
Низкий

7.3 High

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-918